How to Create a Bybit API Key Safely
Learn how to create a Bybit API key, select trade-only permissions, protect the secret and prepare it for a future Crypto Pulse connection.
Use a separate, trade-only key.
For Bybit, enable Account read, positions and order placement. Keep Withdrawal permission and access to products you will not use disabled. Restrict the key by IP whenever possible and revoke it immediately if the secret may be exposed.
Before you create the Bybit API key
An API key lets software send authenticated requests to an exchange account. It is not a wallet seed phrase, but incorrect permissions can still create serious risk. Complete these checks first:
- Use the Bybit website: the current official guide says API-key creation is completed on the web platform.
- Enable Google Authenticator or another supported 2FA method before starting.
- New accounts may face a temporary API-key creation restriction during the first 48 hours.
How to create a Bybit API key
- 01
Sign in to Bybit on the web and open API Management from the account menu.
- 02
Choose Create New Key and select a system-generated API key.
- 03
Name the key clearly so it is not confused with keys used by other services.
- 04
Grant account-reading, position and order permissions only for the products you intend to trade.
- 05
Apply an IP restriction when available, complete 2FA and save the API key and secret securely.
Recommended Bybit API permissions
Bybit is shown in the Crypto Pulse roadmap, but it cannot be connected to the portal yet. Do not enter a Bybit secret until the integration is marked available.
How to connect the key to Crypto Pulse
- Save your limits in Trading settings: order sizing, leverage, maximum positions, daily loss stop, slippage, margin mode and allowed markets.
- Open Exchange API in the client portal and select the supported exchange.
- Paste the dedicated API credentials and choose Verify connection.
- Open an active signal and prepare an order preview. Check market, side, order amount, quantity, modeled risk, margin mode and slippage.
Live order submission is disabled. The current Binance flow verifies credentials and calculates previews only.
Bybit API key security checklist
- Create a dedicated key instead of reusing a key from another bot or service.
- Use the smallest possible permission set and keep withdrawals disabled.
- Bind the key to approved IP addresses whenever the exchange supports it.
- Never share an exchange password, 2FA code, seed phrase or wallet private key.
- Delete and recreate the API key if a secret appears in a screenshot, message or log.
- Review active keys regularly and remove credentials you no longer use.
Frequently asked questions
Which permissions should a Bybit trading API key have?
Use only Account read, positions and order placement. Keep Withdrawal permission and access to products you will not use disabled.
What Bybit credentials must be stored?
The connection uses API key + Secret key. Store them securely and never send them in chat or email.
Should withdrawal permission be enabled?
No. A trading integration does not need withdrawal permission. Crypto Pulse will never request it.
Can I connect Bybit to Crypto Pulse now?
Binance connection testing is available to eligible portal accounts. Bybit, OKX and Bitget remain planned integrations. Live order submission is currently disabled.
API security protects access. Risk settings protect the trade.
Configure both before preparing your first order preview.